GitHub Security Lab has revealed that its open-source AI security agent found 24 vulnerabilities in Android applications. Some of the issues were serious enough to allow hidden location tracking and potential account takeovers.
The research shows how AI can help security researchers examine large codebases and spot complicated mobile security problems. However, the findings still need to be checked and tested by human security experts.
How the AI Security Agent Works
The research used GitHub Security Lab’s Taskflow Agent, an open-source framework built to support AI-assisted security testing.
Instead of giving an AI model a huge codebase and asking it to find everything, researchers divided the investigation into smaller tasks designed specifically for Android.
One workflow looked for important Android entry points, including:
- Exported activities and services
- Broadcast receivers
- Deep links
Another workflow then checked these areas for common Android security problems, such as unsafe intents, insecure broadcasts, WebView issues, and cross-app attacks.
This approach helped the AI focus on the parts of an application that could be exposed to other apps or external input.
OsmAnd Flaw Could Reveal User Locations
One of the notable vulnerabilities was found in OsmAnd, a popular Android navigation application with more than 10 million downloads.
Researchers discovered that its exported MapActivity could accept certain attacker-controlled settings through Android intents.
A malicious app installed on the same device could use these inputs to silently change OsmAnd settings. One possible attack could redirect map-tile requests to a server controlled by the attacker.
By watching the requests, an attacker could potentially determine where a user was located and track movements. Routing information, including starting points and destinations, could also be exposed.
The concerning part is that the victim could continue using the navigation app normally without realizing anything had changed.
Wikipedia Bugs Could Lead to Account Takeover
Another serious chain was found in the Wikipedia Android app.
The application uses a wikipedia:// deep link to open content inside its WebView. Researchers found that the app used an unsafe domain check that looked at whether a hostname simply ended with wikipedia.org.
That means a domain such as evil-wikipedia.org could potentially pass the check even though it was not an official Wikipedia domain.
Researchers also identified another weakness involving cookie handling. When combined, the issues could potentially expose authentication information to an attacker-controlled webpage.
This could give an attacker access to a victim’s Wikimedia session and potentially lead to account takeover after the victim interacts with a malicious link.
AI Helps Researchers, But Humans Still Matter
GitHub emphasized that AI-generated security findings should not automatically be treated as confirmed vulnerabilities.
AI models can be useful for identifying suspicious code, APIs, and attack paths, but they can also produce false positives or misunderstand how a vulnerability behaves in a real environment.
Researchers found that asking the AI to create a proof of concept can help determine whether a suspected issue is actually exploitable. Even then, human testing remains an important part of the process.
The Taskflow Agent and the Android security workflows have been made publicly available, giving security researchers another way to use AI for structured mobile application testing.